# \[php & mySQL\] advice

**URL:** <https://forum.kirupa.com/t/php-mysql-advice/138471>\
**Category:** Uncategorized\
**Created:** [February 22, 2005, 10:55pm UTC](https://forum.kirupa.com/t/php-mysql-advice/138471 "2005-02-22T22:55:17Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![b\_rich](https://avatars.discourse-cdn.com/v4/letter/b/53a042/32.png) [@b\_rich](https://forum.kirupa.com/u/b_rich)\
**Post date:** [February 22, 2005, 10:55pm UTC](https://forum.kirupa.com/t/php-mysql-advice/138471/1 "2005-02-22T22:55:17Z")

</div>

I have a script that inserts variables into a database something like:

INSERT INTO `table_name` (`text1`,`text2`,`text3`,`text4`) VALUES (’$text1’, ‘$text2’, ‘$text3’, ‘$text4’)

as you can see it puts the variables directly into the database, now if one of those variables has a **’** in it it would mess up the the sql statement. How should I avoid this? I was thinking of using **str\_replace** and replace **’** with **’** but that doesn’t work. Any Ideas? I know there is a simple solution I just can’t think of it right now.

Thanks.
